Malicious PDF — malware analysis report

Static analysis result for SHA-256 78b1ca2fec5dc3fb…

MALICIOUS

PDF

15.7 KB Created: 2019-04-30 02:34:31 +01:00 Authoring application: mPDF 5.7
MD5: f229ef1984b4ec75781833db4c277b86 SHA-1: 57e385d0c9a60301addab93bb90c2310e93f9cac SHA-256: 78b1ca2fec5dc3fb97463d556b5e49e67832d3354a80f41a29a9334c5066bd2f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a critical heuristic for containing a mass external link farm, with numerous URLs pointing to the same dominant host, xiixmcuin.linkpc.net. While the extracted document body text is heavily corrupted, the presence of a large number of external links suggests a malicious intent, possibly for SEO manipulation or to redirect users to phishing or malware distribution sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8202206202202207/No-Kava-For-Johnny-by-John-O-39-Grady.pdf
    • http://xiixmcuin.linkpc.net/8202206202204201/Natural-Alternatives-to-Antidepressants-St-John-s-Wort-Kava-Kava-and-Others-by-Kenneth-McIntosh.pdf
    • http://xiixmcuin.linkpc.net/4205208203202203/Johnny-Zed-by-John-Gregory-Betancourt.pdf
    • http://xiixmcuin.linkpc.net/1204200206204/The-Mummy-the-Will-and-the-Crypt-Johnny-Dixon-2-by-John-Bellairs.pdf
    • http://xiixmcuin.linkpc.net/4206209200201202/The-Spell-of-the-Sorcerer-s-Skull-Johnny-Dixon-3-by-John-Bellairs.pdf
    • http://xiixmcuin.linkpc.net/1208204204202203/The-Curse-of-the-Blue-Figurine-Johnny-Dixon-1-by-John-Bellairs.pdf
    • http://xiixmcuin.linkpc.net/4206208202200208/The-Curse-of-the-Blue-Figurine-Johnny-Dixon-1-by-John-Bellairs.pdf
    • http://xiixmcuin.linkpc.net/4206202204203202/Handsome-Johnny-The-Life-and-Death-of-Johnny-Rosselli-Gentleman-Gangster-Hollywood-Producer-CIA-Assassin-by-Lee-Server.pdf
    • http://xiixmcuin.linkpc.net/1208204202207208/Johnny-and-the-Bomb-Johnny-Maxwell-3-by-Terry-Pratchett.pdf
    • http://xiixmcuin.linkpc.net/1206201204207204/Johnny-and-the-Dead-Johnny-Maxwell-2-by-Terry-Pratchett.pdf
    • http://xiixmcuin.linkpc.net/2203203201207202/A-Necessary-Evil-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/2208203202200202/Johnny-Vegas-Johnny-Book-Book-2-by-Nick-Tory.pdf
    • http://xiixmcuin.linkpc.net/8202206202200203/Before-Evil-Maggie-O-Dell-0-5-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/1205207207204201/A-Perfect-Evil-Maggie-O-Dell-1-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/4203209208204/A-Perfect-Evil-Maggie-O-Dell-1-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/4202209204203204/A-Perfect-Evil-Maggie-O-Dell-1-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/9201201204202/Profile-Split-Second-The-Soul-Catcher-At-the-Stroke-of-Madness-by-Alex-Kava.pdf
    • http://xiixmcuin.linkpc.net/1205207207201203/Interment-by-Reg-Grady.pdf
    • http://xiixmcuin.linkpc.net/2202202205207/Red-Planet-Noir-by-D-B-Grady.pdf
    • http://xiixmcuin.linkpc.net/1204205203202207/I-Could-Read-The-Sky-by-Timothy-O-39-Grady.pdf